Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
02:12:00 | Win2K-f | 79.49.40.22 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA NET, ROME, LAZIO, IT. (DSL) |
n/a | :in1.7cy.net :zgoogle.info US:searchportal.information.com US:trafficconverter.biz :xz.ub9.net US:autoinsurancemap.info EE:www.starman.ee FI:194.215.38.3:80 US:204.152.184.139:80 EE:62.65.192.24:80 98.126.46.210:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:47:00 | Win2K-f | 190.178.27.191 (COM.AR): TELEFONICA DE ARGENTINA, AR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org EU:getmyip.co.uk 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
14:00:00 | Win2K-f | 84.98.248.244 (GAOLAND.NET): DYNAMIC POOLS, PARIS, ILE-DE-FRANCE, FR. (DSL) |
n/a | US:msn.com 174.133.57.140:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http http 35 lines |
Argh : 0.3 profile |
none | summary tarball |
25 of 40 | bcb00c51ad NEW |
none[none] | none:none |
none|none | none | none |
14:07:00 | Win2K-f | 78.106.209.73 (CORBINA.RU): BROADBAND CUSTOMERS IN MOSCOW, MOSCOW, MOSCOW CITY, RU. (DSL) |
218.93.205.30:65520 | US:cnn.com CN:giopnon.cn EU:colopin.cn 174.133.57.140:80 CN:218.93.205.19:80 EU:91.206.201.39:80 |
445 | pcap | raw alerts ruleset |
irc 27 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:25:00 | Win2K-f | 186.97.36.221 (EMTEL.NET.CO): COLOMBIA MVIL, TOCAIMA, CUNDINAMARCA, CO. (DSL) |
68.178.232.100:80 | :in1.7cy.net US:downloadfreewares.info US:as.casalemedia.com :pagead2.googlesyndication.com US:images-pw.secureserver.net :imagesak.godaddy.com US:activex.microsoft.com US:www.w3.org US:msn.com :www.godaddy.com US:cdn.optmd.com :download.macromedia.com US:i.casalemedia.com US:fpdownload2.macromedia.com US:128.30.52.38:80 US:204.152.184.139:80 US:64.208.108.98:80 |
445 | pcap | raw alerts ruleset |
http irc 60 lines |
Yeah : 0.8 profile |
none | summary tarball |
0 of 41 | e1205ef060 NEW |
none[none] | none:none |
none|none | none | none |
20:30:00 | Win2K-f | 92.72.219.240 (ARCOR-IP.NET): ARCOR-DSL-NET, BOCHUM, NORDRHEIN-WESTFALEN, DE. (DSL) |
n/a | US:microsoft.com US:fitnessmassager.com US:zoo.parkingspa.com US:rc10.overture.com US:www.drugstore.com US:a216.g.akamai.net US:a1624.g.akamai.net US:a1468.g.akamai.net US:www.paypal.com US:204.152.184.139:80 US:64.208.108.113:80 US:64.208.108.90:80 |
445 | pcap | raw alerts ruleset |
http irc http http 312 lines |
Argh : 0.3 profile |
none | summary tarball |
0 of 40 | 40d00cf1d0 NEW |
none[none] | none:none |
none|none | none | none |
20:36:00 | Win2K-f | 61.189.193.152 (-): CHINANET GUIZHOU PROVINCE NETWORK, SHANGHAI, SHANGHAI, CN. (DSL) |
n/a | US:yahoo.com :tampaeasteregghunts.com US:honestfarm.com US:images01.tzimg.com US:domdex.com US:204.152.184.139:80 US:208.70.72.89:80 |
445 | pcap | raw alerts ruleset |
http irc 33 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:43:00 | Win2K-f | 92.242.82.70 (KIS.RU): BUSINESS COMMUNICATION AGENCY LTD, NOVGOROD, NOVGOROD, RU. (DSL) |
n/a | US:microsoft.com :apvpwjebx.com US:pxusathbcz.org US:bbohsaxrk.org :qvdyehhwuzg.org :eturqiljvfy.net :eterqglfytu.org :vjltoxha.net NL:extlkp.org :dogoaomqfxc.biz :mxuxtf.com :puyevle.com :kfupnz.com :lukzqhfm.net US:sctyukhzpho.org US:ahmyvbkqj.org :gvxkrmkfapl.com :gtbtlq.com :mtzawkedx.biz NL:fmfeynmgzp.org :kwmft.com US:204.152.184.139:80 US:208.70.72.89:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
irc http 29 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:26:00 | Win2K-f | 173.20.115.46 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, ALBANY, GEORGIA, US. (DSL) |
n/a | FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |